Regulation (EU) 2026/1744 is remembered on this desk as the act that moved the high-risk deadline. That is the smaller half of what it did. It also added a prohibition, shortened a transitional period, and moved a sandbox obligation, and each of those changes carries a date of its own. Read alongside the revised Product Liability Directive, which the Omnibus does not touch at all, the result is a cluster of three obligations inside nine days of December 2026, sitting exactly one year before the deadline most organisations have written in their calendars.

In short
  • Regulation (EU) 2026/1744 added a prohibition on AI systems generating child sexual abuse material and on systems depicting an identifiable person's intimate parts without consent. Systems already on the market must comply by 2 December 2026.
  • The same act shortened the Article 50(2) machine-readable marking transitional period, which now ends on 2 December 2026. The Commission's proposal would have run it to 2 February 2027. That longer date was not adopted and should not appear in any plan.
  • Directive (EU) 2024/2853, the revised Product Liability Directive, must be transposed by Member States by 9 December 2026. It has its own legal basis and was untouched by the Omnibus.
  • 2 December 2026 and 2 December 2027 are different deadlines one year apart. The first is prohibitions and marking. The second is the deferred Annex III high-risk regime, including the Article 26 deployer duties.
  • Nothing about supervision was deferred. Since 2 August 2026 the transparency and governance rules apply and the AI Office and the Member State authorities hold responsibility for implementing, supervising and enforcing the Act.

Section 1. What the Omnibus actually did, in five parts

The Digital Omnibus on AI began as COM(2025) 836, presented on 19 November 2025 as a targeted amendment to Regulation (EU) 2024/1689. It reached political agreement on 7 May 2026, received final Council approval on 29 June 2026, and entered into force on 27 July 2026, six days before the original high-risk application date. The adopted act is Regulation (EU) 2026/1744.

Public coverage of that passage concentrated almost entirely on the deferral, which is understandable: the deferral was the contested question for eight months and it is the change with the largest immediate operational consequence. But the adopted act made five distinct changes, and four of them create or move dates. Set out plainly:

What the Omnibus changed Operative date Who it reaches
Deferred the Annex III stand-alone high-risk obligations 2 December 2027 Providers and deployers of stand-alone high-risk systems, including the Article 26 deployer duties
Deferred the Annex I high-risk obligations for AI embedded in regulated products 2 August 2028 Manufacturers and deployers of AI embedded in products already covered by Union harmonisation legislation
Added a prohibition on AI systems that generate child sexual abuse material, and on systems that depict an identifiable person's intimate parts without consent 2 December 2026 for systems already on the market Anyone placing such a system on the market or putting it into service in the Union, at any risk classification
Shortened the Article 50(2) machine-readable marking transitional period Ends 2 December 2026 Providers of systems generating synthetic audio, image, video or text content
Moved the deadline for national AI regulatory sandboxes 2 August 2027 Member States, and indirectly any operator planning to use a sandbox route

Two further changes carry no new date but matter for how the rest reads. The Omnibus simplified the registration of exempted systems in the EU database, and it extended AI Office oversight to certain systems built on general-purpose models and embedded in very large online platforms and search engines. It also amended Article 4 on AI literacy, which is covered separately below.

The one-character error. In the fortnight after 27 July, this desk saw more than one internal compliance calendar in which "2 December 2027" had been entered as the single new AI Act milestone, and the December 2026 obligations had been absorbed into it as though they were the same event. They are a year apart and they reach different populations. A provider of a synthetic media tool has a December 2026 problem and no December 2027 problem at all. A deployer of an Annex III recruitment system has the reverse. Very few organisations have both, which is precisely why merging them is easy and expensive.

Section 2. The new prohibitions, and why they behave differently from everything else

The Omnibus added a prohibition. That is an unusual thing for an act granting a deferral to do, and it deserves more attention than it has received. Two categories of system are now prohibited: AI systems that generate child sexual abuse material, and AI systems that depict an identifiable person's intimate parts without consent. Systems already on the market have until 2 December 2026 to comply.

A prohibition is structurally unlike every other obligation in this regulation, and organisations that have spent two years building documentation practices should register the difference clearly. The high-risk regime under Articles 9 to 17 and Article 26 is a regime of conditions: it permits the activity provided the operator does specified things and can evidence having done them. A prohibition permits nothing. There is no risk management system, no oversight register and no technical file that converts a prohibited practice into a lawful one. The compliance question is binary, and it is answered by inspecting what the system can produce rather than by inspecting what the organisation wrote down about it.

The Article 99 penalty structure reflects that difference in kind. Infringement of the Article 5 prohibitions attracts the top ceiling, up to EUR 35,000,000 or 7 per cent of total worldwide annual turnover, whichever is higher. Other operator obligations sit at up to EUR 15,000,000 or 3 per cent, and supplying incorrect, incomplete or misleading information at up to EUR 7,500,000 or 1 per cent. For small and medium-sized enterprises and start-ups the applicable ceiling is the lower of the two figures in each pair rather than the higher. National market surveillance authorities enforce this regime. A separate regime under Article 101 applies to providers of general-purpose AI models, capped at 3 per cent of annual total worldwide turnover or EUR 15,000,000, whichever is higher. That second regime sits with the AI Office.

The practical question for a European deployer is narrower than the prohibition sounds. Most organisations do not deploy systems whose purpose is anything of this kind. The exposure, where it exists at all, is in general-purpose image and video generation capability that has been embedded into a product or made available to staff or customers without an assessment of what it will produce when asked. That is a capability question, not a policy question, and it is answered by testing rather than by reading a vendor's acceptable use policy. Organisations offering any generative image or video capability to external users should treat the period between now and 2 December 2026 as the window to establish and record what their deployment can and cannot generate.

Section 3. Article 50(2): the transitional period that got shorter, not longer

This is the change most likely to be recorded wrongly, because it moved in the opposite direction to the headline.

Article 50 of Regulation (EU) 2024/1689 sets the transparency obligations. They applied from 2 August 2026 and they were not deferred by the Omnibus. Article 50(2) is the machine-readable marking limb: providers of AI systems generating synthetic audio, image, video or text content must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The Commission's Omnibus proposal attached a transitional period to that duty running to 2 February 2027. The adopted act shortened it. It ends on 2 December 2026.

There is a specific reason this matters more than a two-month difference usually would. The February 2027 figure was live on this site, and on a great deal of other published material, during the period between proposal and adoption. It was accurate when written and became wrong on 27 July 2026 without anything visible happening to the page carrying it. Anyone whose Article 50 planning was set during that window, and not revisited since, is likely to be working to a date that exists only in a superseded proposal. If a marking implementation plan in your organisation names February 2027, that plan was built from the proposal rather than from the act.

Article 50 splits along the provider and deployer line more sharply than most of the regulation. The marking duty in Article 50(2) sits on providers of generative systems. The disclosure duties reach deployers: a person interacting with an AI system should be told, and certain generated or manipulated content should be disclosed as such. An organisation that buys a generative capability and puts it in front of customers is typically a deployer for disclosure purposes and not a provider for marking purposes, unless it has modified the system in a way that shifts its role under Article 25. The full treatment of that boundary is on this site in the Article 25 value chain guide, and the transparency duties themselves in the Article 50 deployer guide.

The Article 50 question worth answering before December

One inventory, four columns

  1. Every AI output in the estate that reaches a human or a machine reader, including outputs embedded inside another product's interface.
  2. For each: are we the provider, the deployer, or both, applying Article 25 rather than the commercial contract as the test.
  3. For each: what disclosure is made today, in what words, at what moment in the interaction.
  4. For each output that is synthetic audio, image, video or text: what marking the upstream provider applies, confirmed with the provider rather than assumed, and whether it survives our processing pipeline.

The fourth column is the one that produces surprises. Marking applied by a model provider does not necessarily survive re-encoding, cropping, format conversion, or passage through a content management system. An organisation relying on an upstream provider's marking should confirm that the marking is still present in what its own users actually receive, and should do that before December rather than after a supervisor asks.

Section 4. 9 December 2026: the deadline outside the AI Act entirely

Directive (EU) 2024/2853 on liability for defective products must be transposed into national law by every Member State by 9 December 2026. It sits outside Regulation (EU) 2024/1689, outside the Omnibus, and outside any part of the negotiation that produced the deferral. No proposal before the Parliament, the Council or the Commission moves it.

The reason it belongs in a December 2026 briefing rather than in a separate one is the reading error that follows from treating the Omnibus as general relief. An organisation that concluded in late July that its AI liability exposure had moved to 2027 has, without noticing, also concluded something about a directive the Omnibus does not touch. Once transposed, AI software falls within the product liability regime, and the evidentiary provisions matter as much as the substantive ones: a claimant's ability to obtain disclosure of evidence from a defendant reaches the documentation an organisation kept about how its system was built, monitored and corrected.

This produces the counterintuitive result at the centre of the current European position. The Article 26 documentation set, whose regulatory deadline moved out by sixteen months, is also the evidentiary record that becomes relevant in a product liability claim from December 2026 onward. The regulatory clock moved. The litigation clock did not. An organisation that stood down its documentation programme in July on the strength of the deferral has reduced its regulatory exposure for 2027 and increased its evidential exposure for 2027, which is not the trade most boards think they made. The interaction is treated at length in the double-exposure guide on this site.

Section 5. What was never deferred, and is enforceable today

The Omnibus deferred two obligation sets. It is worth stating the remainder as a list, because the deferral has been read in a great many places as broader than it is.

Obligation Applies since Status after the Omnibus
Article 5 prohibited practices 2 February 2025 Unchanged, and extended by the two new prohibitions from 2 December 2026
Article 4 AI literacy 2 February 2025 Amended, not repealed. The obligation remains on providers and deployers; no specific level is mandated
General-purpose AI model provider obligations 2 August 2025 Unchanged
Article 50 transparency 2 August 2026 Unchanged, with the Article 50(2) marking transitional period ending 2 December 2026
Supervision and enforcement architecture 2 August 2026 Unchanged. The AI Office and the Member State authorities hold implementation, supervision and enforcement responsibility

The Article 4 amendment is the subtlest of these and the easiest to misread in either direction. AI literacy remains an obligation on providers and deployers. What the Omnibus removed was the mandating of a specific or sufficient level, with the Commission and Member States taking a stronger role in promoting literacy instead. For a deployer of a high-risk system, the duty to train staff so that human oversight is real remains in place. Supervision and enforcement of it commenced on 2 August 2026, with the national market surveillance authorities. Two readings are wrong: that Article 4 was untouched, and that it was repealed. Both have appeared in circulation. The certification consequences of the amendment, specifically what training evidence an assessment can still ask for when the yardstick has been removed, are treated on agentcertified.eu.

Section 6. A working calendar from here

The useful output of all of this is a single ordered list. What follows is the sequence this desk would work in an organisation that has done nothing since July.

August to September 2026

Phase: establish which of the three December obligations reach you

  1. Test, do not survey, any generative image or video capability exposed to staff or customers against the two new prohibited categories. A vendor policy statement is not the evidence; the system's behaviour is.
  2. Build the Article 50 inventory described in Section 3. Four columns, every output, no exceptions for capability embedded inside a third-party product.
  3. Search internal planning documents for "2 February 2027" and for any Article 50 milestone set between November 2025 and July 2026. Those dates came from the proposal.

October to November 2026

Phase: close the marking and disclosure position

  1. Confirm with each upstream generative provider what marking they apply and in what format, in writing, and verify it survives your own processing pipeline end to end.
  2. Fix disclosure wording at the point of interaction rather than in a policy page. Article 50 disclosure is about what the person in front of the system is told, at the moment they are in front of it.
  3. Confirm the national market surveillance contact point for your Member State, ahead of any need to use it.

November to December 2026

Phase: the product liability record

  1. Treat the Article 26 documentation set as an evidential record with a December 2026 relevance date rather than a regulatory file with a December 2027 deadline. The two dates are not alternatives.
  2. Confirm how your Member State has transposed Directive (EU) 2024/2853, since transposition is national and the detail will vary.
  3. Review the insurance position on the same evidence base. What an underwriter asks for and what a claimant can seek disclosure of have converged considerably, and the practical guidance for that is on agentinsured.eu.

Questions

What happens on 2 December 2026 under the EU AI Act?

Two things happen on 2 December 2026. First, the new prohibitions introduced by Regulation (EU) 2026/1744, the AI Omnibus, take effect for systems already on the market: AI systems that generate child sexual abuse material, and AI systems that depict an identifiable person's intimate parts without consent, must comply by that date. Second, the transitional period for the machine-readable marking obligation in Article 50(2) of Regulation (EU) 2024/1689 ends on that date. A third deadline sits one week later: Member States must transpose Directive (EU) 2024/2853, the revised Product Liability Directive, by 9 December 2026.

Did the AI Omnibus delay the Article 50 transparency obligations?

No. It shortened one of them. The Article 50 transparency obligations applied from 2 August 2026 and were not deferred. The AI Omnibus shortened the transitional period attached to the Article 50(2) machine-readable marking duty, which now ends on 2 December 2026. The Commission's original proposal would have run that period to 2 February 2027; the adopted act did not. Any planning document still working to February 2027 for machine-readable marking is working to a date that was not adopted.

Is 2 December 2026 the same deadline as 2 December 2027?

No, and the one-year gap between them is the most common source of confusion in current compliance calendars. 2 December 2026 is the date the new Omnibus prohibitions bite for systems already on the market and the date the Article 50(2) marking transitional period ends. 2 December 2027 is the deferred application date for the Annex III stand-alone high-risk obligations, including the Article 26 deployer duties. The Annex I high-risk obligations for AI embedded in regulated products move separately to 2 August 2028.

Does the Product Liability Directive deadline depend on the AI Act timeline?

No. Directive (EU) 2024/2853 on liability for defective products has its own national transposition deadline of 9 December 2026, set in the directive itself. It is a separate instrument with a separate legal basis, and nothing in the AI Omnibus touches it. An organisation that reads the AI Act deferral as general relief on AI liability is reading across two regimes that were never linked.

Are the AI Act enforcement powers themselves delayed?

No. From 2 August 2026 the transparency and governance rules apply, and the AI Office and the authorities of the Member States are responsible for implementing, supervising and enforcing the AI Act. The deferral changed the application dates of specific high-risk obligation sets. It did not defer the supervisory architecture, the prohibitions in Article 5, the Article 4 AI literacy duty, the general-purpose AI obligations, or the penalty regime.

What should a deployer do between now and December 2026?

Three things, in order. Confirm whether any system in the estate falls inside the two new prohibitions, because a prohibition admits no documentation defence. Identify every AI output that reaches a person or a machine reader and confirm the Article 50 disclosure and marking position for each, since the marking transitional period closes on 2 December 2026. Then treat the Product Liability Directive transposition on 9 December 2026 as a documentation question rather than a legal one, because the evidence a claimant can seek is evidence the organisation either kept or did not.

Sources

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L, 12.7.2024.
  2. Regulation (EU) 2026/1744, the Digital Omnibus on AI, OJ L, 2026/1744. Proposal COM(2025) 836 of 19 November 2025; political agreement 7 May 2026; Council final approval 29 June 2026; entry into force 27 July 2026. European Commission, AI Omnibus enters into force, checked 17 August 2026.
  3. European Commission, AI Act Service Desk, timeline for implementation of the EU AI Act, checked 17 August 2026. Source for the application dates of 2 August 2026, 2 December 2026, 2 August 2027, 2 December 2027 and 2 August 2028.
  4. Article 50, Regulation (EU) 2024/1689. Transparency obligations for providers and deployers of certain AI systems, including the Article 50(2) machine-readable marking duty.
  5. Article 99, Regulation (EU) 2024/1689. Penalties. Ceilings of EUR 35,000,000 or 7 per cent, EUR 15,000,000 or 3 per cent, and EUR 7,500,000 or 1 per cent of total worldwide annual turnover, whichever is higher in each case, with the lower figure applying to SMEs and start-ups. European Commission, AI Act Service Desk, Article 99, checked 17 August 2026.
  6. Article 101, Regulation (EU) 2024/1689. Fines for providers of general-purpose AI models, not exceeding 3 per cent of annual total worldwide turnover or EUR 15,000,000, whichever is higher. European Commission, AI Act Service Desk, Article 101, checked 17 August 2026.
  7. Article 4, Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. European Commission, AI literacy questions and answers, checked 17 August 2026.
  8. Article 25, Regulation (EU) 2024/1689. Responsibilities along the AI value chain, including the circumstances in which a deployer becomes a provider.
  9. Directive (EU) 2024/2853 of the European Parliament and of the Council on liability for defective products, OJ L, 18.11.2024. National transposition deadline 9 December 2026.
  10. Article 6 and Annex III, Regulation (EU) 2024/1689. Classification rules for high-risk AI systems, application deferred to 2 December 2027 by Regulation (EU) 2026/1744.